ServiceNow is a prominent enterprise workflow and IT service management platform with a focused product portfolio spanning its core service-management suite, AI agent extensions, and API-driven integrations that serve as operational backbone systems for many organizations. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated tendency toward confirmed in-the-wild exploitation and widespread public exploit availability, reflecting the platform's role as a high-value target and its exposure through web-tier and API attack surfaces. The recurring exposure concentrates in weakness classes including cross-site scripting, code injection, unnecessary privilege execution, and information disclosure, which are characteristic of large, multi-tenant application platforms handling sensitive business logic and access controls. Defenders should prioritize ServiceNow advisories and treat the platform as a critical patching target given its breadth of integration and administrative reach; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by ServiceNow over time
Of all the CVEs published by ServiceNow as a CNA, 50.0% affect products that ServiceNow develops as a vendor.
Of all the CVEs published that affect products developed by ServiceNow, 61.1% are self-published by ServiceNow as a CNA.
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5217CRITICAL ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable a | Jul 10, 2024 | 9.8 | 98 | YES | YES |
CVE-2024-4879CRITICAL ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthentica | Jul 10, 2024 | 9.8 | 98 | YES | YES |
CVE-2025-12420CRITICAL A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the imperson | Jan 12, 2026 | 9.8 | 61 | NO | NO |
CVE-2022-38463MEDIUM ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality. | Aug 23, 2022 | 6.1 | 32 | NO | YES |
CVE-2024-8923CRITICAL ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code | Oct 29, 2024 | 10.0 | 31 | NO | NO |
CVE-2022-39048MEDIUM A XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade an authenticated user to click a | Apr 10, 2023 | 6.1 | 31 | NO | YES |
CVE-2021-45901MEDIUM The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists. | Feb 10, 2022 | 5.3 | 29 | NO | YES |
CVE-2018-7748HIGH report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Injection in the sysparm_media par | Aug 3, 2018 | 8.8 | 28 | NO | NO |
CVE-2024-8924HIGH ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to extract unauthorize | Oct 29, 2024 | 7.5 | 24 | NO | NO |
CVE-2022-43684MEDIUM ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality.
Additional Details
This issue is present | Jun 13, 2023 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by ServiceNow.
Media articles that mention a CVE ID that affects a product developed by ServiceNow — matched by CVE ID, not by vendor name.